Trust Center

Before you put your band's gigs, contracts and money records into any new tool, you deserve straight answers about where that data lives, who can see it, and how you get it back. Here they are.

Last updated: July 23, 2026

Who's behind this

GigBookerAI is built and run by working musicians — not a faceless software company. It exists because our own band was held together by group texts, spreadsheets, scattered PDFs and calendar screenshots, and we got tired of it. So we built the system we wished we had.

The company is SCJON Enterprises LLC, based in the Dallas–Fort Worth area. GigBookerAI is a registered trademark; the source code is federally copyright-registered. We are actively developing the product every week and are personally reachable — the same people who wrote the code answer your support requests.

— The GigBookerAI team, SCJON Enterprises LLC

🔐 Security & infrastructure

Concrete specifics — not "enterprise-grade" hand-waving.
Encryption in transit
Every connection uses HTTPS/TLS. Your data is never sent over an unencrypted link.
Encryption at rest
Your database and file storage are encrypted at rest by our infrastructure providers (Supabase on AWS).
Authentication
Sign-in is handled by Supabase Auth. Passwords are salted and hashed — we never see or store them in plain text.
Row-level security
Every database table enforces row-level security: you can only read the bands, gigs and records you're actually part of. This is enforced at the database, not just in the app.
Backups
The database is backed up automatically every day by our database provider, with point-in-time recovery available on our plan.
Hosting
Front end on Vercel (global CDN). Database, auth and file storage on Supabase. Both are established, widely-used platforms.

👁 Who can see your data

Your bandmates
Only what their role allows. Members see gig details and contract terms but not pay amounts; agents see what they book; venues see only their own shows. Sensitive money data is scoped by role.
Other bands / venues / agents
No access to your private data. Public discovery only shows what you deliberately publish (your EPK, availability as busy/open — never the details).
Us
We can access data only when you ask us to help (support, setup, a bug you report). We don't browse customer records, and we never sell or share your data with anyone.

🤖 How AI is used — and what it does with your data

Straight answer to "what does the AI actually do, and does it train on my data?"
What it does
AI helps you draft outreach — venue pitches, follow-ups and quotes (the "✨ Draft with AI" button) — and powers the GigBot setup assistant. You always review and edit before anything sends.
Which model
Anthropic's Claude, called through our own secure server (your browser never talks to the AI provider directly, and no keys are exposed).
What's sent
Only the specific context needed to draft what you asked for (e.g. the band and venue name for a pitch). Not your finances, member SSNs, or contracts.
Does it train on your data?
No. We use Claude via Anthropic's API, which does not use API inputs to train its models. Your data is not fed into any AI training set.

📦 Your data is yours — ownership, export & deletion

WhatWhere it stands
OwnershipYou own your gigs, contacts, contracts, set lists and financial records. Full stop.
Export today NowTax summaries, equipment lists and fan email lists export to CSV. Contracts download as PDF. Calendar events are viewable/printable.
"Export everything" ComingA one-click full export (CSV / PDF / ICS / ZIP) is on the near-term roadmap. Until then, email us and we'll export your full account for you.
Account deletion ComingSelf-service delete is coming. Today, email us and we'll delete your account and data on request. You can already delete individual bands and remove your own roles yourself.
After cancellationYour records stay accessible so you can export them; nothing is purged out from under you. We'll always give you a window to get your data before anything is removed.

🔗 Third-party services we use

The complete list of who touches your data, and why.
ServiceWhat it does
SupabaseDatabase, authentication and file storage (encrypted, row-level secured).
VercelHosts and serves the web app over HTTPS.
ResendSends the app's email (invites, contracts, notifications) from our verified domain.
Anthropic (Claude)Powers the AI drafting features. Does not train on your data.
GoogleVenue search (Places) and web fonts.
Meta (Facebook / Instagram)Advertising measurement on our public home and sign-up pages only — it never loads inside the app, and it never sees your band, gig, contract or earnings data. Details.

🛟 If something goes wrong — and how to reach us

Security incidents
If a breach ever affected your data, we would notify you promptly and directly, tell you what happened, and what we're doing about it. We won't hide it.
Outages
If the app is down, your data is safe in encrypted, backed-up storage — an outage is a "can't reach it right now," not a "lost it."
Support response
We reply to support requests within one business day. Gig-day problems get priority — we know a Saturday-night issue can't wait until Monday.
Reach us
Contact page, or the in-app feedback button on every page (it goes straight to us).
An honest note on maturity: GigBookerAI is a young product in active beta, built by a small team of working musicians. We don't yet carry formal third-party certifications (like SOC 2), and we won't pretend otherwise. What we do have: sound, standard security practices; real people who answer you; and a commitment to keep this page honest as we grow. Keep your current records in parallel while you evaluate us — that's exactly what we'd tell a friend to do.
See what's live & what's next →